Recap: New York Payment Startup Exposed Credit Card Numbers, Delta Denies Discussing Presale Of Miles & More

View Comments (6)

  • Amex is saving their money to bail themselves out when consumers don’t pay their cc according to that earnings report today...

  • The problem isn't that the server wasn't password protected -- that's bad but eventually that kind of lapse will happen -- the problem is the data was stored as plain text. Security is created by having layers of protections, not relying on the sysadmin to remember to put passwords on every server migration.

    Data security is a bit of a catch-22 -- everyone talks about how "critical" it is but then every data breach class action pays out at 20 cents per case, suggesting the data isn't really worth much. Courts need to do their part if we expect companies to change

    • I would argue both are heinous. You're right that Defense-in-Depth is the real strategy, but missing either of those basic controls are grave mis-steps for any sysadmin or architect.

    • Correct, the penalty for breaches for the company needs to be so harsh that implementing better processes for others becomes the better alternative.

    • And also a big pet peeve -- settlements requiring you to use a third party commercial company for credit monitoring if you don't already have it, instead of taking a cash payout. Court mandated profits for that company. Great.

      • You are always free to opt out of a class action settlement and pursue an individual claim for damages.